CrowdStrike Conducts External Review to Better Understand What Triggered the Global Outage

The root cause analysis conducted by external vendors has revealed an interprocess communication (IPC) template type error.

Advertisement
Written by Akash Dutta, Edited by Siddharth Suvarna | Updated: 7 August 2024 16:05 IST
Highlights
  • CrowdStrike did not name the vendors performing the external review
  • The CrowdStrike outage occurred on July 19
  • The outage affected Windows laptops and desktops globally

Microsoft services such as Office 365 and Azure were affected during the CrowdStrike outage

Photo Credit: Unsplash/Windows

CrowdStrike, the US-based cybersecurity firm, caused a global outage on July 19 after an update resulted in Windows laptops and desktops crashing and getting stuck in a boot loop. The outage lasted multiple hours affecting different sectors including airlines, healthcare, IT, and more. After fixing the issue, the company published a post-incident report highlighting that its artificial intelligence (AI) system dubbed 'Falcon sensor' caused an error. Now, the company has published a detailed report after conducting an external review to highlight what exactly went wrong.

CrowdStrike Publishes External Review Report

In a report titled ‘External Technical Root Cause Analysis — Channel File 291', the cybersecurity firm said it found that the Falcon sensor deployed an erroneous template type string which affected Windows interprocess communication (IPC) mechanisms.

As per CrowdStrike, Falcon runs machine-learning models that automatically identify and remediate the latest and advanced threats from bad actors. Right before the July 19 outage, the detection functionality pushed a new “template type” to millions of computers of customers' Falcon installations in version 7.11.

Advertisement

However, this is where things went wrong. The report highlighted that the IPC template type had defined 21 input parameter fields but “the integration code that invoked the Content Interpreter with Channel File 291's Template Instances supplied only 20 input values to match against.” This mismatch is usually not a concern since so far the AI system has never picked an input outside the given 20.

Advertisement

But on that day, the sensor asked to inspect template type 21. Since there was no corresponding integration code relating to it, the attempt to access the 21st input parameter created an out-of-bounds memory error and resulted in a system crash.

Highlighting steps for mitigation, the report claimed that CrowdStrike developed a patch for the Sensor Content Compiler that validates the number of inputs provided by a Template Type. This went into production on July 27. The firm said that it has also focused on increased testing and validation before pushing an update. Further, it has also stated that all future updates will be rolled out in a phased manner to minimise any potential error.

Advertisement

Notably, no details about the external vendors who conducted the review were provided.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: CrowdStrike, Microsoft Hub, Laptops
Advertisement

Related Stories

Popular Mobile Brands
  1. Top OTT Releases of the Week: Kantara Chapter 1, Lokah Chapter 1, Idli Kadai, and More
  2. iQOO 15 Indian Variant Allegedly Surfaces on Geekbench Ahead of Launch
  3. Samsung Galaxy Book 6 Pro Allegedly Listed on Geekbench With These Specs
  1. Starlink Hiring for Payments, Tax and Accounting Roles in Bengaluru as Firm Prepares for Launch in India
  2. Google's 'Min Mode' for Always-on Display Mode Spotted in Development on Android 17: Report
  3. OpenAI Upgrades Sora App With Character Cameos, Video Stitching and Leaderboard
  4. Samsung's AI-Powered Priority Notifications Spotted in New One UI 8.5 Leak
  5. Samsung Galaxy S26 Series Could Feature Model Slimmer Than Galaxy S25 Edge With New Name
  6. iQOO 15 Colour Options Confirmed Ahead of November 26 India Launch: Here’s What We Know So Far
  7. Vivo X300 to Be Available in India-Exclusive Red Colourway, Tipster Claims
  8. OpenAI Introduces Aardvark, an Agentic Security Researcher That Can Find and Fix Vulnerabilities
  9. Xiaomi 17, Poco F8 Series and Redmi Note 15 Listed on IMDA Certification Website Hinting at Imminent Global Launch
  10. CERT-In Warns Google Chrome Users of High-Risk Flaws on Windows, macOS, and Linux
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.